SafePay Ransomware is a ransomware-as-a-service (RaaS) threat that emerged in September 2024 and was described as a rapidly emerging and sophisticated ransomware operation. In reporting on 2025 ransomware activity, it was listed among the top RaaS groups by attack volume, with 452 attacks, placing it behind Qilin, Akira, and Clop and ahead of Play in the cited ranking. Supporting reporting also states that CYFIRMA observed an underground-forum claim that SafePay ransomware compromised 47CLUB in Japan and that the compromised data contained confidential and sensitive information. Based on the provided content, SafePay is associated with ransomware operations and data-compromise claims, but no additional high-confidence technical details on malware behavior, encryption methods, infection vector, file extensions, ransom note names, or specific indicators of compromise were provided.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware (RaaS) operation listed among the highest-volume groups by recorded attacks in 2025.
Emerging ransomware operation (first identified Sep 2024) described as fast-moving and using double extortion; noted to capitalize on VPN weaknesses and credential theft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.